[Snort-sigs] About the ICMP reply

Sun snortmaillist at ...2420...
Thu Jan 3 00:50:48 EST 2008

Hi all,

    I'm confused by the reply in class of ICMP.

    For example, 'ICMP Timestamp Request' are from external to home, but 
the 'ICMP Timestamp Reply' is still from external to home, then how can 
we detect the reply from the home server?

    Furthermore, 'ICMP Address Mask Reply' are from home to external, 
but 'ICMP Address Mask Reply undefined code' are from external to home, 
while these too alert are only different at the 'undefined code'.

    Consider the task of the snort is to protect the user in home net, I 
think the request should be external to home, while the reply should be 
home to external. If the external server is also concerned, it should be 
another set of alerts to describe the attack.

    Can any body tell me whether my above oponion is correct or not?

    Best regards



More information about the Snort-sigs mailing list